CVE-2019-25234 Details
Description
SmartHouse Webapp 6.5.33 contains multiple cross-site request forgery and cross-site scripting vulnerabilities that allow attackers to perform unauthorized actions. Attackers can exploit these vulnerabilities by tricking logged-in users into visiting malicious websites or injecting malicious scripts into various application parameters.
Multiple cross-site request forgery (CSRF) and cross-site scripting (XSS) vulnerabilities have been identified in Carlo Gavazzi SmartHouse Webapp version 6.5.33. These vulnerabilities allow attackers to perform unauthorized actions by tricking logged-in users into visiting malicious websites or by injecting harmful scripts into various application parameters. The vulnerabilities arise because the application does not properly validate HTTP requests, enabling actions to be performed with administrative privileges. Additionally, several GET and POST parameters are vulnerable to XSS, allowing the execution of arbitrary HTML and script code in the context of the affected site.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Dec 24, 2025CISA-ADP
Assessed Dec 24, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5543.php | CISA-ADP | AdvisoryBundleExploit |
| https://www.exploit-db.com/exploits/47730 | [email protected] | Exploit |
| https://www.zeroscience.mk/en/vulnerabilities/ZSL-2019-5543.php | [email protected] | AdvisoryBundleExploit |
| http://www.smarthouse.nu | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-352 | Cross-Site Request Forgery (CSRF) | [email protected] |
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Carlo Gavazzi SmartHouse Webapp | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Dec 24, 2025 | CVE Modified | CISA-ADP |
| Dec 24, 2025 | New CVE Received | [email protected] |
Volerion